Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1119 Multiple Plugins - Cross-Site Scripting From Third-party Library — WP-Optimize 6.1 -2023-07-10
CVE-2023-3077 MStore API < 3.9.8 - Unauthenticated Blind SQLi — MStore API 9.8 -2023-07-10
CVE-2023-3076 MStore API < 3.9.9 - Unauthenticated Privilege Escalation — MStore API 8.1 -2023-07-10
CVE-2023-2578 Buy Me a Coffee < 3.7 - Admin+ Stored XSS — Buy Me a Coffee 4.8 -2023-07-10
CVE-2023-2493 All In One Redirection < 2.2.0 - Admin+ SQLi — All In One Redirection 7.2 -2023-07-10
CVE-2023-2796 EventON < 2.1.2 - Unauthenticated Event Access — EventON 5.3 -2023-07-10
CVE-2023-3129 URL Shortify < 1.7.0 - Admin+ Cross Site Scripting — URL Shortify 4.8 -2023-07-10
CVE-2023-1273 ND Shortcodes < 7.0 - Subscriber+ LFI — ND Shortcodes 6.5 -2023-07-04
CVE-2023-2320 CF7 Google Sheets Connector < 5.0.2 - Reflected XSS — CF7 Google Sheets Connector 6.1 -2023-07-04
CVE-2023-2321 WPForms Google Sheet Connector < 3.4.6 - Reflected XSS — WPForms Google Sheet Connector 6.1 -2023-07-04
CVE-2023-3460 Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation — Ultimate Member 9.8 -2023-07-04
CVE-2022-4623 ND Shortcodes < 7.0 - Contributor+ Stored XSS via Shortcodes — ND Shortcodes 5.4 -2023-07-04
CVE-2023-3139 Protect WP Admin < 4.0 - Unauthenticated Protection Bypass — Protect WP Admin 4.3 -2023-07-04
CVE-2023-2010 Forminator < 1.24.1 - Unauthenticated Race Condition on poll vote — Forminator 5.3 -2023-07-04
CVE-2023-2324 Elementor Forms Google Sheet Connector < 1.0.7 - Reflected XSS — Elementor Forms Google Sheet Connector 6.1 -2023-07-04
CVE-2023-3133 Tutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API — Tutor LMS 5.3 -2023-07-04
CVE-2023-2333 Ninja Forms Google Sheet Connector < 1.2.7 - Reflected XSS — Ninja Forms Google Sheet Connector 6.1 -2023-07-04
CVE-2023-2605 WP Brutal AI < 2.0.1 - Admin+ Reflected XSS — wpbrutalai 6.1 -2023-06-27
CVE-2023-2795 CodeColorer < 0.10.1 – Admin+ Stored Cross-Site Scripting — CodeColorer 4.8 -2023-06-27
CVE-2023-2326 Gravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF — Gravity Forms Google Sheet Connector 6.5 -2023-06-27
CVE-2023-0588 Catalyst Connect Zoho CRM Client Portal < 2.1.0 - Reflected XSS — Catalyst Connect Zoho CRM Client Portal 6.1 -2023-06-27
CVE-2023-2624 KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting — KiviCare 6.1 -2023-06-27
CVE-2023-2628 KiviCare Management System < 3.2.1 - Multiple CSRF — KiviCare 8.1 -2023-06-27
CVE-2023-1166 USM Premium < 16.3 - Admin+ Stored XSS — Ultimate-Premium-Plugin 4.8 -2023-06-27
CVE-2023-2623 KiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure — KiviCare 6.5 -2023-06-27
CVE-2023-2592 FormCraft Premium < 3.9.7 - Admin+ SQLi — FormCraft 7.2 -2023-06-27
CVE-2023-2068 File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode — file-manager-advanced-shortcode 9.8 -2023-06-27
CVE-2023-2711 Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS — Ultimate Product Catalog 4.8 -2023-06-27
CVE-2023-1891 Accordion & FAQ < 1.9.9 - Reflected XSS — Accordion & FAQ 6.1 -2023-06-27
CVE-2023-2842 WP Inventory Manager < 2.1.0.14 - Inventory Items Deletion via CSRF — WP Inventory Manager 4.3 -2023-06-27

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.